← Back to search

CVE-2026-67243

7.2 HIGHpublic exploit available

Published 2026-08-04 · Updated 2026-08-04

AI risk analysis

Summary
This vulnerability allows an admin to upload and execute arbitrary files, leading to remote code execution.
Exploitability
Exploitation requires administrative privileges but is straightforward once obtained.
Blast radius
If exploited, it could lead to full control over the affected system, including data theft or destruction.
Prioritized remediation
Update to the latest version of freo2 that addresses this vulnerability.
rceadmin-privilegeupload-vuln

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.